{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/e-hr--8.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hongjing:e-hr:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-54399"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["e-HR (\u003c 8.2)"],"_cs_severities":["critical"],"_cs_tags":["web-application","injection","vurnerability"],"_cs_type":"threat","_cs_vendors":["Hongjing"],"content_html":"\u003cp\u003eHongjing e-HR versions prior to 8.2 contain a critical SQL injection vulnerability residing in the /servlet/codesettree endpoint. The application fails to properly sanitize the 'categories' query parameter after stripping HRMS-specific encoding, allowing an unauthenticated remote attacker to inject malicious SQL syntax. This vulnerability permits the execution of UNION SELECT statements, which can be leveraged to query arbitrary tables within the backend database. Defenders should note that this flaw can be exploited to exfiltrate sensitive data, including administrative credentials from the operuser table. This vulnerability has been subject to active exploitation in the wild since October 2023, as identified by the Shadowserver Foundation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to sensitive corporate data. By targeting credential tables such as operuser, attackers can obtain account information, facilitating further unauthorized access to the HR management system and potentially lateral movement within the network. This affects organizations utilizing Hongjing e-HR globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Hongjing e-HR to version 8.2 or higher immediately to address the underlying vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the /servlet/codesettree endpoint to reject requests containing SQL keywords or metacharacters in the categories parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for suspicious HTTP requests targeting /servlet/codesettree containing UNION, SELECT, or character manipulation strings.\u003c/li\u003e\n\u003cli\u003ePerform a security audit of the backend database to check for unauthorized access or dumped credential records following the timeline of observed exploitation (since October 2023).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T20:06:56Z","date_published":"2026-09-18T20:06:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hongjing-ehr-sql-injection/","summary":"Hongjing e-HR versions prior to 8.2 are vulnerable to unauthenticated SQL injection via the categories parameter in the /servlet/codesettree endpoint, allowing remote attackers to extract sensitive database content.","title":"SQL Injection in Hongjing e-HR /servlet/codesettree","url":"https://feed.craftedsignal.io/briefs/2026-09-hongjing-ehr-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - E-HR (\u003c 8.2)","version":"https://jsonfeed.org/version/1.1"}